New Tradecraft of Iranian Cyber Group Aria Sepehr Ayandehsazan aka Emennet Pasargad


The Federal Bureau of Investigation (FBI), U.S. Department of Treasury, and Israel National Cyber Directorate are releasing this Cybersecurity Advisory (CSA) to warn network defenders of new cyber tradecraft of the Iranian cyber group Emennet Pasargad, which has been operating under the company name Aria Sepehr Ayandehsazan (ASA) and is known by the private sector terms Cotton Sandstorm, Marnanbridge, and Haywire Kitten.

The group exhibited new tradecraft in its efforts to conduct cyberenabled information operations into mid-2024 using a myriad of cover personas, including multiple cyber operations that occurred during and targeting the 2024 Summer Olympics – including the compromise of a French commercial dynamic display provider. ASA has also undertaken a project to harvest content from IP cameras and used online resources related to Artificial Intelligence.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter


Related:

  • Cyber Security & Cloud Congress North America Unveils Esteemed Speaker Lineup

    February 26, 2024

    The Cyber Security & Cloud Congress North America has revealed the newest additions to its speakers’ line up for its forthcoming conference, slated to be held at the Santa Clara Convention Center on June 5-6, 2024. Among the notable speakers set to take the stage are: Alissa “Dr Jay” Abdullah, Deputy Chief Security Officer – Mastercard Benjamin Benhan, ...

  • Lockbit cybercrime gang says it is back online following global police bust

    February 26, 2024

    Lockbit, the cybercrime gang that was knocked offline by a comprehensive international police operation earlier this month, says it has restored its servers and is back in business. The group, notorious on the internet’s criminal underground for using malicious software called ransomware to digitally extort its victims, was the target of an unprecedented international law enforcement ...

  • The Building Resilience to Cognitive Warfare Technical Exchange Meeting

    February 23, 2024

    In September 2023, MITRE hosted a Technical Exchange Meeting (TEM) titled Building Resilience to Cognitive Warfare with participants from MITRE, the Department of Defense, and the Australian Defense Force, whic h focused on securing the cognitive domain, including identifying national-level partnerships and innovation opportunities. This paper explores the emerging importance of cognitive security in the face ...

  • AT&T, T-Mobile and Verizon users hit by massive cellular outage in US

    February 22, 2024

    Mmajor cellphone outage affected users across the US early Thursday — even stopping some police departments from being able to receive 911 calls. AT&T seemed to have experienced the largest number of issues, with nearly 32,000 reports at around 4:30 a.m., according to data from DownDetector, which tracks outages by collating status reports from sources including ...

  • FBI issues warning against using Chinese manufactured drones

    February 21, 2024

    Chinese-manufactured unmanned aircraft systems (UAS), more commonly known as drones, continue to pose a significant risk to critical infrastructure and U.S. national security, according to an FBI advisory. While any UAS could have vulnerabilities that enable data theft or facilitate network compromises, the People’s Republic of China (PRC) has enacted laws that provide the government with ...

  • Law enforcement disrupt world’s biggest ransomware operation

    February 20, 2024

    In a significant breakthrough in the fight against cybercrime, law enforcement from 10 countries have disrupted the criminal operation of the LockBit ransomware group at every level, severely damaging their capability and credibility. LockBit is widely recognised as the world’s most prolific and harmful ransomware, causing billions of euros worth of damage. This international sweep follows ...